Manage Certificate Exclude List
24706
Created On 09/25/18 20:34 PM - Last Modified 07/29/20 23:00 PM
Symptom
Administrators have more control over the certificate exclude lists in PAN-OS 8.0. PAN-OS maintains a pre-defined certificate exclude list that lists the CNs of certificates for which SSL decryption is bypassed. PAN-OS 8.0 grants administrators access to this list, delivered via content update, via GUI and CLI and allows admins to enable/disable pre-defined entries and add custom entries to the existing list.
Environment
- PAN-OS 8.0
Resolution
Additional Information
- The hostname in the SSL Decryption Exclusion is case sensitive. Please look into following example:
PA-3060(active)> test ssl-exclude-list predefined hostname whatsapp.net Hostname 'whatsapp.net' is excluded from decryption PA-3060(active)> test ssl-exclude-list predefined hostname Whatsapp.net Hostname 'Whatsapp.net' is not excluded from decryption PA-3060(active)>